2 Comments

How to learn the first bit of m in padded RSAThank you. I think (0^k||r||00000000) is like a head tag of any message, so when I decrypt m', the head is fixed. I think 2^e c modN=(2m')^e mod N, but I don't know what the connect with m.